
EC-CouncilCertified SOC Analyst
Domain 6Objective 1
Incident Response Process CSA Practice Questions (Page 6)
Part of the Incident Response, Forensics and Cloud SOC domain, which makes up ~23% of our current practice bank.
56questions here
12free pages
9concepts
Questions 26–30
- 26
Which section should be included in an incident report to provide a chronological account of the incident?
Select an answer first - 27
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 28
A SOC analyst is investigating a possible data breach. The analyst has logs from the firewall, the authentication server, and the file server. Which correlation would most strongly indicate a data breach?
Select an answer first - 29
After an incident has been contained and eradicated, what is the primary goal of the recovery phase?
Select an answer first - 30
A company has confirmed a ransomware infection on a file server. The malware is actively encrypting files. The incident response team needs to stop the spread while preserving evidence. Which containment action should be taken FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSA” is a trademark of its owner, used for identification only.